From nobody Thu Sep 24 23:32:04 2026 Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E25494F6460 for ; Fri, 18 Sep 2026 13:16:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.76 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789737388; cv=none; b=rSgNoxz+dSpwvSV01DFTzQnyyK73BfJbYDUG0fN15M2V0hKgYbzMe+/mub7yT7gfCrsF7qeiXH7uybHIhjJmFKI7H9hRizw/MPJhmY5rYuD9xmkOcBaZh+Mp48fzQoQ3lf5YNpxPmJa1JIGjLJR55yu8eIgr6oYoFs6mmMYN3eQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789737388; c=relaxed/simple; bh=3fBo8hNW0MWM/bX/SqnAHR9KMvYrbDBSWDD9TTtMK6M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=cvEvvNxXeaBeL0cXIrN+madkjEYY0HcyfMZMZy6huxh65w32n2bvpMn9AcJg8QVOliBeuzTp1xLTI2/+gchR63S1XxE3nu6y4njCbdEJv675q01gInHEVBceULiXKAB7hT/994riwTSPEdhg2+/agyf99eT8J1GyMvCLAGgmuvM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=p2fF8MEw; arc=none smtp.client-ip=74.125.225.76 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="p2fF8MEw" Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-48437356d60so375188f8f.3 for ; Fri, 18 Sep 2026 06:16:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789737384; x=1790342184; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=FZS4CiCQN/3yr16/M/PFmnufnsKta51fgde7Cv0nVKI=; b=p2fF8MEwh2Y9L3C5O3HFUi4yy25LTdFmjDyUkIaMxclTnRzBSf6cYRoZq3KeEOnC+D KSfExV6SKRqk0F6tsIM7uZhgfnfL/CoFoWu7LQeOOGhZln3HJCO8l/3EnT+00oEy+Af2 EJcucINk7+egYyMygbJL3AGFip5smUqLiq0Dnwl0DtPz/5SHHHAcKukLYXwfjQ65XPlK solHDye+ChDdr1VeA8MmG5D9x+MwRUUwTuuPD4M8UgV2I+bGtvacHje6k22K2EhegOjD JVHrLWTRWEGxsYZvPjHIImYcWOghvjJS9tNMs5qL0ADy9EjvQLOpYbgd5NXFyAyGeFjM HOrw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789737384; x=1790342184; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=FZS4CiCQN/3yr16/M/PFmnufnsKta51fgde7Cv0nVKI=; b=qcZzqoanCjyRh5+1Z4OZDBaZYETGsv4lkJEpP7HAxAa8OH08E5DlVamGG//ZL8+gcE 6ze9lhiq040zgyyXafHUF475jb/xbeBUWrUlcqkXrYUj4LmG1Eg3AfuvLfTthWx7ndzp 1++PP6FJMzamii99gN3KuO5r/rJY6KvgVcIoy58jI5+mhgevl75MsJMvhjGS5+ONwd5z urUabbP0LcjfQDAWgEnyjOM457Y7PuYt5iD40TVanN0z98HSrAap9WcxSxIa6Bq5Yfry Q4dHQ/jvSAKxCTTnxXCQ0M/QjO2aTgebG5VmJ6LqwbH15uMaabqhlbUA6VUf4MMPPbRD RhsA== X-Forwarded-Encrypted: i=1; AKwUvBwmtorhPXvloj0p6zwNg/n1AGHh8aEQERglre8TfiyCQZGTDrG5IXfd8bAQDq8wWIHgxXUenxrRtI6pxhA=@vger.kernel.org X-Gm-Message-State: AFuF++mCDBR2w2v6egbJoP+APtqOyjuD/1YtLVmtxLaPwJSoS/VVqRR8 oJIgi5xrjCcC5DY29jU/DqLiEmRSUhmWUTNWb0cHCvu3kV5v1Sc1zSRz X-Gm-Gg: AYBFou1yUhBlQBMHSRs943tiiE6zjk+Q2ST5MK857nCoOKJkgGrolsBEQzhtVaIGhnO dF4bNZ+RyhjTUrS+z3s4DDGf5ovNDxsh1oSj6eGIfpC/04MABqr/HVk4Tb9xNnrNbh0ZRvDpAhj 8oXEptA/wPYvGKo5Qd3BysvjYv1DSZcmZhPNBT1ptb1m0mmYaWmb+u+44WvuicPFB2ZOErTjChc UaaUaR4zD/p1zwq3+vI1JiO5rYmmVzpmakD9lnCpMhLiOSC/2lLEdrsRVJ4AEJCfY0mTUfNEt6x Db9yK+rMQnunRb+3eoi7xOhAvx6SrAyF8xmovOYG0V+8RhXwN6GnXkzWWvha1+w/ViWJw2qpz/U oFMe4ee4tQXjS67bmSTyrGplH5Rcy0L2/2ymcCXnR+LY3eTEKdd0MsCBOoUZVitdiVV6+kMoA+c qU36otVcHB+/SzO1dSmFpSghSW10iaD7xQKVlC7C+X6szGT4pzWluS1HmGBBQqmqw3UfSmsBa78 zPfs0G5NS4= X-Received: by 2002:a05:6000:70f:b0:487:b50:101c with SMTP id ffacd0b85a97d-4871e215a94mr3116370f8f.5.1789737383660; Fri, 18 Sep 2026 06:16:23 -0700 (PDT) Received: from fra-x8664.wind3.hub ([151.16.209.67]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-487200829e1sm4487572f8f.34.2026.09.18.06.16.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 18 Sep 2026 06:16:23 -0700 (PDT) From: Francesco Magazzu To: Lyude Paul , Danilo Krummrich Cc: dri-devel@lists.freedesktop.org, nouveau@lists.freedesktop.org, linux-kernel@vger.kernel.org, Dan Carpenter , Karol Herbst Subject: [PATCH v3 1/4] drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update Date: Fri, 18 Sep 2026 15:16:17 +0200 Message-ID: <20260918131620.405133-2-postadelmaga@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260918131620.405133-1-postadelmaga@gmail.com> References: <20260918131620.405133-1-postadelmaga@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Dan Carpenter If list_for_each_entry() exits without hitting a break then "pstate" is not a valid pstate pointer. Introduce a "found" variable instead. The check is reachable from userspace: nvkm_clk_ustate_update() takes the pstate id straight from the 'pstate' debugfs file, so requesting an id that is not in clk->states - or any id at all when the perf tables are broken and the list is empty - makes the pstate->pstate !=3D req test dereference the list head cast to a struct nvkm_pstate, which is an out-of-bounds read. Fixes: 7c8565220697 ("drm/nouveau/clk: implement power state and engine clo= ck control in core") Signed-off-by: Dan Carpenter [Francesco: rebased on drm-misc-next, expanded the commit message] Signed-off-by: Francesco Magazzu Reviewed-by tags, rebase on drm-misc-next. --- This is Dan's 2022 patch, reposted with his authorship restored as asked in the review of v2. The diff is byte for byte what he sent; the commit message keeps his original two sentences and adds a paragraph on how the check is reached from userspace. Link: https://lore.kernel.org/dri-devel/YvSkKAdk8Pe0g2K9@kili/ drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c b/drivers/gpu/d= rm/nouveau/nvkm/subdev/clk/base.c index 572e63846..5da82db71 100644 --- a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c +++ b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c @@ -473,6 +473,7 @@ static int nvkm_clk_ustate_update(struct nvkm_clk *clk, int req) { struct nvkm_pstate *pstate; + bool found =3D false; int i =3D 0; =20 if (!clk->allow_reclock) @@ -480,12 +481,14 @@ nvkm_clk_ustate_update(struct nvkm_clk *clk, int req) =20 if (req !=3D -1 && req !=3D -2) { list_for_each_entry(pstate, &clk->states, head) { - if (pstate->pstate =3D=3D req) + if (pstate->pstate =3D=3D req) { + found =3D true; break; + } i++; } =20 - if (pstate->pstate !=3D req) + if (!found) return -EINVAL; req =3D i; } --=20 2.55.0 From nobody Thu Sep 24 23:32:04 2026 Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CA20A4F3EA8 for ; Fri, 18 Sep 2026 13:16:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.76 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789737388; cv=none; b=EOZRSQcrR9xszBqMdgKd1KBju6ElxVNtb0+G+7qwmzFdVvlr/sty+A7Ek4a7lvdgACc67uTsuinwtWRsE3+EBnx9zpaRG0GYi79JmftIKewct9FSVdGxXrGorI3cwmCIqrUwp+MgaK7oDmHSPC/I/xyzP6rYCHghO+q6D8Kpq4M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789737388; c=relaxed/simple; bh=4iYlSPBFdYVbmaQ+n6xg76xhNoVAGw/DSdwQgm6frLA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=KLV0S7K2nh/SdM76LWIZV3Nti7f1AK/6YfgzO1WWjbQjQHfVUnEJQFptmqy/32O75BiZwpUX9ggOKLb8mcMr1JbLGJVECn7hjFGkABOY27gi6wX0sUjEJbOs0VmRgIzv4qFwI0/uC+QwtC4MsGZBk2L8BtjIghVRjv/AmS74G4U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=J+7+ZeDA; arc=none smtp.client-ip=74.125.225.76 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="J+7+ZeDA" Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-4858bc96fabso583284f8f.3 for ; Fri, 18 Sep 2026 06:16:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789737385; x=1790342185; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NPknZ1WGs+5VI15GYbHYggwlCsBgDjKJicFWFVELHwY=; b=J+7+ZeDA+gXPKSKz4aNcyf874ZousFOxqqC3Y6bQTSTzeafyAqzpy8Q7R7E+uLA92D /+ykZWKfqB1I/rq4K/BQrtTUu10gVGh52vL8FvJ9yKZOKRiudAV7aDLgcOnGuRg6nxpm PtCIBu/ktVpuUpFlhhheO5H7G5gOiJveXEQUXnoDEVqX9Wv55CIY48EiX/KLOaMMR4uY /J0CMFZIDtQE+2QNY9T0cshPNudznFy8qdEEZiu+n2KoSYZAEKf+cG053r8oLnGYroA8 WacZjNV6jBMclMaP08DUrrcXVQyvZa79keP80GpsARCIMRtWyD3dTtRydpqvPs7J+gYa M++A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789737385; x=1790342185; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=NPknZ1WGs+5VI15GYbHYggwlCsBgDjKJicFWFVELHwY=; b=o9enhyVO+ldM5GfW/xsywAYY1s3Aani2Tsee7+Xpf7+Rx7Kq1Jtzusmtvc8NKuLwNB pVGwgs/Xk7+f0OibL6UCNkB2letSUERW3F4oC5VAvu34hLtBYXM1qtmffPmD4itqBs/C wJUkZPqWOcyDnGZNPbXgQAOj08wtcKA6tdCGO/jiHmnWstHb6J9jYvFvZLlNeU8wRfeb QK0T6TJ5pNOPvhQPFvYre3vBDGszL3KmQfMo64s0F22stwGlcUaF4nRwZp+WSDmiVBjf /bZ6/KeO5Ua+qQLstul3QZP4Z0ZSmIPFJKXUcp4GRv6jXEvtd3QQlS3T06oyFRr57Wi1 YuAg== X-Forwarded-Encrypted: i=1; AKwUvBwhmwBnVEgXIy8DHE7fSgR3xqtKr2tmuWP9D/I6yOlE9PRK3+0dAWhRHu+IaHNLalDMws4x0YZgujeHZfY=@vger.kernel.org X-Gm-Message-State: AFuF++nJwrjI8HytdfXZfBSNQxdBZNf7JuLK9cYhLoD0LDkQcxH7yHV4 7CXgRm5TzTC7h61P5YZCamA0GmEvP7LdKypx9ShiqgGeVG5XtxUnIQLf X-Gm-Gg: AYBFou2u4qfPuD0e/Zu8Dkr28HAtgbVAw48Q9khGAoXP1KZSOgkr2SixEOu4z6fnKZQ rm/4IhsnAF/upiOB8/3Wmmdptz9DngX1AC/GWss8uptuOzSHplF9XO0C3kQo8KL2lJKoP9tNI5Q 3FbhaFo5lb0iT7B8FKvJRnSE5G8GWWKE81if10X1prtpR7tr/HDmLeTx9U1z1nfHy9MswDzJPUs UkR/pXmL3kljyB8UDyWZjtpJ/RV3nPXzH01OlWVIl77a5hIpr2TPw1408kIvIcy2/iBRJiLic4E NqHtJxe67xNehXuzKEj4c123T9j2RJomUk/ogUbPPv0ArCvIQ/dytNqZBuNCmf/IQueqYZ+aCEk bR2nuwuczxVXkJ9eOIT8W+GMXPMxe8IeTa7sTsfV4Yen85oTKAEML4E4dncKvcVkJdSQcgIhYPO lwZ6d/wq6Elf2p1KMin9xa7Xra+dW0UCxH7KiVRxuoyiev+np/8lhMo780VQMAj8WmKG3yIL5xg 8mbBD4ZWKU= X-Received: by 2002:a05:6000:4548:b0:487:221f:a2e1 with SMTP id ffacd0b85a97d-487221fa2f6mr1255469f8f.55.1789737384792; Fri, 18 Sep 2026 06:16:24 -0700 (PDT) Received: from fra-x8664.wind3.hub ([151.16.209.67]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-487200829e1sm4487572f8f.34.2026.09.18.06.16.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 18 Sep 2026 06:16:24 -0700 (PDT) From: Francesco Magazzu To: Lyude Paul , Danilo Krummrich Cc: dri-devel@lists.freedesktop.org, nouveau@lists.freedesktop.org, linux-kernel@vger.kernel.org, Dan Carpenter , Karol Herbst Subject: [PATCH v3 2/4] drm/nouveau/clk: don't use the pstate cursor after the loop Date: Fri, 18 Sep 2026 15:16:18 +0200 Message-ID: <20260918131620.405133-3-postadelmaga@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260918131620.405133-1-postadelmaga@gmail.com> References: <20260918131620.405133-1-postadelmaga@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nvkm_pstate_prog() walks clk->states looking for the entry at index 'pstatei' and then keeps using the list_for_each_entry cursor after the loop. This is not triggerable today: every caller clamps the index against clk->state_nr before calling, so the loop always breaks on a real entry. It is safe by virtue of what the callers happen to do, not by anything the function itself checks. Should a caller ever pass an index that is not on the list, the cursor would point at the list head rather than at a pstate, and the pstate->base.domain[] and pstate->fanspeed accesses that follow would read past it. Rather than leave that trap in place for the next caller, track whether the entry was found and return -EINVAL if it was not. No functional change. Signed-off-by: Francesco Magazzu Reviewed-by: Lyude Paul Reviewed-by tags, rebase on drm-misc-next. --- drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c b/drivers/gpu/d= rm/nouveau/nvkm/subdev/clk/base.c index 5da82db71..a43246ae6 100644 --- a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c +++ b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c @@ -270,13 +270,19 @@ nvkm_pstate_prog(struct nvkm_clk *clk, int pstatei) struct nvkm_fb *fb =3D subdev->device->fb; struct nvkm_pci *pci =3D subdev->device->pci; struct nvkm_pstate *pstate; + bool found =3D false; int ret, idx =3D 0; =20 list_for_each_entry(pstate, &clk->states, head) { - if (idx++ =3D=3D pstatei) + if (idx++ =3D=3D pstatei) { + found =3D true; break; + } } =20 + if (!found) + return -EINVAL; + nvkm_debug(subdev, "setting performance state %d\n", pstatei); clk->pstate =3D pstatei; =20 --=20 2.55.0 From nobody Thu Sep 24 23:32:04 2026 Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 090714F3920 for ; Fri, 18 Sep 2026 13:16:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.76 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789737391; cv=none; b=mt7RQAEf7iPxDVarOobEm66hJhlHoQmxdBIXcojoQCckl+Km6UR1KTyNM+AR+jDFy6yL3xaUllu3cQTB06h2FZxUswMnFCRamvebCd/+MLwNvPo816ioPjVS5PegeKXCOkxuT6+FDyNMEazY0QDOxB3whYNF1z07Y3fGdy0TMo8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789737391; c=relaxed/simple; bh=AziE3Yj7NTzqiNMtlJscqQncplQWikmCngG3C9eD4oU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=N38ZvyjgBumjyEKfrnw1dnvhr6/lw+GOOthxE3MQqkaBITFK+rRyXCSBOgUWwF8o4gw016AY5shVcdFTsmuJNnWrmw/KGdOXO9bYwl7Q3/zLl4NAMhZarqQu/cu4/FARlm4ohp+89PWZtWllRI622NNUKd84sh989iKoNuoCBuE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ku1ruZox; arc=none smtp.client-ip=74.125.225.76 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ku1ruZox" Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f6350faaso411326f8f.0 for ; Fri, 18 Sep 2026 06:16:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789737386; x=1790342186; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=MWU/Z4Cv9J6Gjygd5g2E8XPN0BiQe/Sbx9hToRJGZ3A=; b=ku1ruZox+vbqHzEVK3Dw4aYrn8v2mGEmjQDn2D32uHP9qvvnHKH3RtsLza9iCBtYES giUyMzx6lqddELSpbclBFB3iupTd6lIquoc73iUQM2zsX4vVKPwi/pHuLpupPYbNUJps Ro3FrmSfEhdZJ94nlsYdPd212sN5K6XWR/KjnB59ihvOow0VLU5rxY8TZBZHy+yV2hzK YBhmw4oYZa0H0PT1Ssf8xyk9STeMxDnyWL+DEjvcL+Ekya484vq151JxK9iA0RkpkINh D6kNN2sJ4EBA73qLBrh9lKoiIcLuu4Ibw9vQAFG1DJ5H1+oCR1Dge9Tz1sq63VngthxQ EVQw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789737386; x=1790342186; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=MWU/Z4Cv9J6Gjygd5g2E8XPN0BiQe/Sbx9hToRJGZ3A=; b=vdczVXFkfyXtewS95wNluOb+GnuhwJe7xX7AK/bIntF4pgweHIOSjmeHIiKiygGaai adjq/FjjXtN1C25L7Lg+Mivqtty14RETiTH3QUhp1xsMV1xx/yblPQ0V7VYgRmj3QeKq COR48UbUw/4WaZmP4TMo0W0r1ff3mQDtsYe0LSGY7VTyr1rxV+KG2lqsiwpJ1BRdTv/3 Y21tEoWyrep51113qnGjIWQqmeM5fpKQlcQFN/xaUVwD11/HNKNMnqvYNGirl4UOluZY AwQ2UrVR7qco3fd5Oaze6OHnGCvh/bDQUNdwZx/E7CHEcZXVdxC52wHIKii8NSOXaFqn Wg7g== X-Forwarded-Encrypted: i=1; AKwUvBzPVnrdrXF6VWH7YrTnJwBMDvhdfjxHdPm5yGHeSX4iRifIiunaZBqkdJaeu9H80N47c0fbaAmIyWoc97M=@vger.kernel.org X-Gm-Message-State: AFuF++ko8oWICizfNZa91BQ1b6bI9/+Xo0Tv88qzzEaxUyenbRX/jfJK BAx6vUueYDklPNwYnXj8OPVuktLclhlnU9YSPgrmiRqQOzKv/3aYcY57 X-Gm-Gg: AYBFou2K456UBt89EK9Lxgdy77YuaMUpvXZqZXL4StZa1oODURZqsWpIJKTKhnmlGrk H9KFuxm+sY9T9VirAa55QeknDjoa7gEAMiF7ViprVUybKihVGSyqr5wXjLyNxrUWCCl9+eWtoCA JCURTViwbx+P3Jtz0l8VcU04t0g8sSByvm1Bexw9fvHN4gnu5D5sHSvbD5Xn4Mn2syR88kauQgl V1e3SGm/3mK7NYqB/lUxz8gALYvJs1+Ct8bugE4eFJSb+sDESbOGNjpQXKBP3fVWFQU83cq2Xov W14L6huB1CFtn+Ryfdaq6TL9VnxDfEm4M/4J14lUs/rIEryO9lebYj58exM1PsEfZEBtzKKZNM6 xJmLtB8gzDEKywBFKZlQF/yhEqNOFB4T57X0r8+3m9FLNNY/BDnb/6eqfgGHctvm0yeiC0h7oS9 9NIaSREWustTIiaZTRzXWCJkJ2pRSgNic1yeTXsOU/PmdxdtpINFai5M6yCpJnoAllNGfaf+E9w UHyR6UeceI= X-Received: by 2002:adf:e19a:0:b0:487:35d:cb0f with SMTP id ffacd0b85a97d-4871e216fc4mr3566538f8f.14.1789737386045; Fri, 18 Sep 2026 06:16:26 -0700 (PDT) Received: from fra-x8664.wind3.hub ([151.16.209.67]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-487200829e1sm4487572f8f.34.2026.09.18.06.16.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 18 Sep 2026 06:16:25 -0700 (PDT) From: Francesco Magazzu To: Lyude Paul , Danilo Krummrich Cc: dri-devel@lists.freedesktop.org, nouveau@lists.freedesktop.org, linux-kernel@vger.kernel.org, Dan Carpenter , Karol Herbst Subject: [PATCH v3 3/4] drm/nouveau/device: don't use the pstate cursor after the loop Date: Fri, 18 Sep 2026 15:16:19 +0200 Message-ID: <20260918131620.405133-4-postadelmaga@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260918131620.405133-1-postadelmaga@gmail.com> References: <20260918131620.405133-1-postadelmaga@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nvkm_control_mthd_pstate_attr() looks up the pstate at the index supplied by userspace by walking clk->states, and then keeps using the list_for_each_entry cursor after the loop. This is not triggerable today: the function already rejects args->v0.state >=3D clk->state_nr before the loop, and clk->state_nr is kept in sync with the number of entries on clk->states, so the lookup always breaks on a real entry. Should the loop ever run to completion, the cursor would point at the list head rather than at a pstate, and the pstate->base.domain[] read and the walk of pstate->list that follow would read past it. Rather than leave that trap in place, track whether the entry was found and return -EINVAL if it was not, like the other lookup failures in this function. No functional change. Signed-off-by: Francesco Magazzu Reviewed-by: Lyude Paul Reviewed-by tags, rebase on drm-misc-next. --- drivers/gpu/drm/nouveau/nvkm/engine/device/ctrl.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/device/ctrl.c b/drivers/gp= u/drm/nouveau/nvkm/engine/device/ctrl.c index f2e9a0626..28702741a 100644 --- a/drivers/gpu/drm/nouveau/nvkm/engine/device/ctrl.c +++ b/drivers/gpu/drm/nouveau/nvkm/engine/device/ctrl.c @@ -74,6 +74,7 @@ nvkm_control_mthd_pstate_attr(struct nvkm_control *ctrl, = void *data, u32 size) const struct nvkm_domain *domain; struct nvkm_pstate *pstate; struct nvkm_cstate *cstate; + bool found =3D false; int i =3D 0, j =3D -1; u32 lo, hi; int ret =3D -ENOSYS; @@ -104,10 +105,15 @@ nvkm_control_mthd_pstate_attr(struct nvkm_control *ct= rl, void *data, u32 size) =20 if (args->v0.state !=3D NVIF_CONTROL_PSTATE_ATTR_V0_STATE_CURRENT) { list_for_each_entry(pstate, &clk->states, head) { - if (i++ =3D=3D args->v0.state) + if (i++ =3D=3D args->v0.state) { + found =3D true; break; + } } =20 + if (!found) + return -EINVAL; + lo =3D pstate->base.domain[domain->name]; hi =3D lo; list_for_each_entry(cstate, &pstate->list, head) { --=20 2.55.0 From nobody Thu Sep 24 23:32:04 2026 Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 308AB4F7CD9 for ; Fri, 18 Sep 2026 13:16:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.76 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789737392; cv=none; b=t9VneThH4+pfSeXxfIsj0izCTXzN9KxLlUYACP1e0XjKXMD9pbZyDw9Rb9W/22MKRwRhiIbGKIFfwey/9IFDnKJlbNhrFarVIsXyaRpgBbbyrRSkFYThY0hJ6AMgjukKi1PZqWPBasz45WlRzNQyfmqKlIxLwBqJiOIvEiHMEmM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789737392; c=relaxed/simple; bh=DbdKlCa2odn2Uw/XyYQhVOEIt2OFS2NRzxTNkQOWfyo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=sqBwyIiPlVQUJOkmAvUoFVKUAtTDm3tlFtV7CwTAALyFDi3hGzOG1UXfBfN4YiXSUwPl8GpwuQ6Lsp+Tus4VQKHwEP0p8ZHzaigWGR7POoWG5GMf7oAs0brQSsLxGOjw2smrWtN3RlJG9AsyUqpmqoUP/Dafyh6m0plmngbgLVY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=lmDYSvW7; arc=none smtp.client-ip=74.125.225.76 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="lmDYSvW7" Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f633cd78so409812f8f.1 for ; Fri, 18 Sep 2026 06:16:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789737388; x=1790342188; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jQCO1lrXpdk3Cfzx3wIoTrVcbxEHs1oQDclhX0KurhE=; b=lmDYSvW7LItvd+GhnbcwDTm75JaoL3BJzoDBuviZFTAwTExnxTX9sBs5eCutXuuYyn utbiawREmlp8iRGe6pDVltJnlHpz3qXvSR2y7QAD97cX96fMT1cHTxHhSyh/4uK9exg9 ebaI44/YQRdAOO16zZojDpWId0wpl+4FzrxlJlFQTgXMoLqw9M1wTskhVIby9ft4g4xg ehtsPuDrfsqi1p/QfRBd6p7iRuPo3x/zd1lVDSUoLBlVyhnzZ7wuWaBwiGes/N6Rsky8 BjsSzxYssAsLQM1kVM07PTUu+EsNP+sHUIzRbhw/Mggr2tjuEy19Uo0zH65petgv77iP 8Plg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789737388; x=1790342188; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jQCO1lrXpdk3Cfzx3wIoTrVcbxEHs1oQDclhX0KurhE=; b=lxO5pZ6iCKBP+vJriqM9q52sBnXlCYR7ffAdL9tjSDPuLOgy45f164Sk1Htn/w29Xh k9i6y/Ezj0YNeSNztBzgXr5L3qHHdc7RHqrdXaeOb/v+fZre9jes9z6q1EPHS6+Ua76K PVaFtPXAQ5Wj6gfX0Y9GHzJRoCgm+knRH6XUQqwKRixhNEaOROwJWp/jhUEltHRTDKgM 4YnUnyW1aAqTHh6Q66zga8M4GXZWntIn8gGeT8n4elOw/BoqOgK7/iUZ0p1w3AP9TMnQ EB1J//UleQg1ZIi+xOLDN45DmiDoq1R1zdQC7OLoeBN8Gw6llMJBd5fPm9qCB+8plEZ7 F8EQ== X-Forwarded-Encrypted: i=1; AKwUvBzE5OxrgmGdCvrC+8Q0musiJ1EjC+QiECkEiWsPw4kprGlIcG699nYv2GPpNGXOccdf5xzngd/qkOXv8TI=@vger.kernel.org X-Gm-Message-State: AFuF++kvnce6xckakfmcC2MECrRCnMGLQ8VFGiFwR9yB6FjtEkicxPcu M1QpyivVRgIc28D6u4bXqoQ7odZFGSMRAcxIyqZGOG/RmG3kmw8VBGhK X-Gm-Gg: AYBFou0/VavgRmibjZ4SpyTaxbTQcZ/jlhblKW1sPwL/DDQV25AqpNprRl0KzDzzd1I VqmztKsjv4SQjhVtnH5JtQK+l8hzJ9yEw0KJWPEiVfV5SolAQGxgLJiUPiMA1q+lJhYa5fCA4hK fBn15Kxo8s6V3g9xkQmzow0TGnM1GeTtlUUqaPllBgVW89a62LMBTOGHmyEhRxaX7rohG24mkK3 L2VVBf23wE58CXxTM0fCWsWrE9QUJ9hBn8MCo6y4Ldi1yJjB7USyhc8vbJ8BfJF3/MAqSXH3yGX U/IO1Dn0scxQvYsJyURZGJUP04iwz8tngQz9STAkj1gkV/aPaDoJGgryAvWcNoTRYS4JynT6vXo E/GE7c6EMbzs3EvchXSqlWElW0CXMErRDzNP5vWivSxOVTrMm+vTssHnIpT8VETGwpF5VTJyJB3 rBuoVm3Cm+ziYZWqVbMtNhuIsgcOcvO7llGdACkGIWlJD3tObdW2KIi33K5sLfwHrdiUqZ/CLmQ mMA2sGd48M= X-Received: by 2002:a05:6000:2312:b0:486:f6dc:52c8 with SMTP id ffacd0b85a97d-4871e269e92mr3590006f8f.37.1789737387367; Fri, 18 Sep 2026 06:16:27 -0700 (PDT) Received: from fra-x8664.wind3.hub ([151.16.209.67]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-487200829e1sm4487572f8f.34.2026.09.18.06.16.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 18 Sep 2026 06:16:26 -0700 (PDT) From: Francesco Magazzu To: Lyude Paul , Danilo Krummrich Cc: dri-devel@lists.freedesktop.org, nouveau@lists.freedesktop.org, linux-kernel@vger.kernel.org, Dan Carpenter , Karol Herbst Subject: [PATCH v3 4/4] drm/nouveau/clk: don't clobber reclock status when restoring volt/fan Date: Fri, 18 Sep 2026 15:16:20 +0200 Message-ID: <20260918131620.405133-5-postadelmaga@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260918131620.405133-1-postadelmaga@gmail.com> References: <20260918131620.405133-1-postadelmaga@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nvkm_cstate_prog() reuses 'ret' for the voltage and fan-speed restore calls it makes after reprogramming the clocks. Those calls almost always succeed, so the status of the reclock itself is overwritten and the function reports success even when clk->func->calc() or clk->func->prog() failed. The converse is also true: a successful reclock is reported as an error if the final restore call fails, even though that failure is only logged and otherwise ignored. The only consumer of the return value is the error message in nvkm_pstate_work(), so in practice a failing reclock is simply never reported. Nothing else changes, but a function that returns success on failure is a trap for the next caller. Keep the calc/prog status in 'ret' and use a separate local for the restore calls. Fixes: 3eca809b3c05 ("drm/nouveau/clk: cosmetic changes") Signed-off-by: Francesco Magazzu Reviewed-by: Lyude Paul Reviewed-by tags, rebase on drm-misc-next. --- drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c b/drivers/gpu/d= rm/nouveau/nvkm/subdev/clk/base.c index a43246ae6..1cb83edc7 100644 --- a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c +++ b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c @@ -199,16 +199,18 @@ nvkm_cstate_prog(struct nvkm_clk *clk, struct nvkm_ps= tate *pstate, int cstatei) } =20 if (volt) { - ret =3D nvkm_volt_set_id(volt, cstate->voltage, - pstate->base.voltage, clk->temp, -1); - if (ret && ret !=3D -ENODEV) - nvkm_error(subdev, "failed to lower voltage: %d\n", ret); + int err =3D nvkm_volt_set_id(volt, cstate->voltage, + pstate->base.voltage, clk->temp, -1); + + if (err && err !=3D -ENODEV) + nvkm_error(subdev, "failed to lower voltage: %d\n", err); } =20 if (therm) { - ret =3D nvkm_therm_cstate(therm, pstate->fanspeed, -1); - if (ret && ret !=3D -ENODEV) - nvkm_error(subdev, "failed to lower fan speed: %d\n", ret); + int err =3D nvkm_therm_cstate(therm, pstate->fanspeed, -1); + + if (err && err !=3D -ENODEV) + nvkm_error(subdev, "failed to lower fan speed: %d\n", err); } =20 return ret; --=20 2.55.0